You've already forked FFmpeg
mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2025-08-04 22:03:09 +02:00
lavc/vvc: Fix derivation of inverse LMCS idx
The clamping of idxYInv from H.266(V3) section 8.8.2.3 was missing. This could lead to OOB reads from lmcs->pivot or input_pivot. I also changed the derivation of the forward LMCS idx to use a shift rather than a division for speed and as this is actually how the variable is declared in the specification (8.7.5.2). Signed-off-by: Frank Plowman <post@frankplowman.com>
This commit is contained in:
@ -835,7 +835,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const H266RawAPS *rlmcs, const H266Raw
|
||||
|
||||
//derive lmcs_fwd_lut
|
||||
for (uint16_t sample = 0; sample < max; sample++) {
|
||||
const int idx_y = sample / org_cw;
|
||||
const int idx_y = sample >> shift;
|
||||
const uint16_t fwd_sample = lmcs_derive_lut_sample(sample, lmcs->pivot,
|
||||
input_pivot, scale_coeff, idx_y, max);
|
||||
if (bit_depth > 8)
|
||||
@ -851,6 +851,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const H266RawAPS *rlmcs, const H266Raw
|
||||
uint16_t inv_sample;
|
||||
while (i <= lmcs->max_bin_idx && sample >= lmcs->pivot[i + 1])
|
||||
i++;
|
||||
i = FFMIN(i, LMCS_MAX_BIN_SIZE - 1);
|
||||
|
||||
inv_sample = lmcs_derive_lut_sample(sample, input_pivot, lmcs->pivot,
|
||||
inv_scale_coeff, i, max);
|
||||
|
Reference in New Issue
Block a user